Security & Data Architecture
Updated 5 September 2026
VAT Guard separates account and billing information from the operational records stored in your encrypted workspace.
Where information is stored
Supplier, invoice, evidence and assessment records are encrypted before being saved in your browser. They are readable in memory while you have the workspace unlocked.
Chrome and Edge can write encrypted workspace files and retained revisions to a folder you select. If that folder is synced through OneDrive, SharePoint or Google Drive, your organisation's sync software transfers it. A successful folder write does not confirm that another device has received it. VAT Guard also retains up to seven daily automatic browser restore points and supports separate encrypted backup exports.
Supabase stores authentication, membership, company and subscription metadata in Frankfurt. Plan-limit coordination uses counts, opaque record identifiers and creation months; it does not require supplier names, invoice amounts or document contents. Cloudflare Pages hosts the app, Stripe handles payments, Resend delivers transactional email and Tilda hosts the marketing page.
Passwords and recovery keys
Your sign-in password and workspace encryption password serve different purposes. Browser cryptography protects the encrypted workspace, with a separate recovery key. Keep the workspace password and recovery key securely outside the browser. SITUS does not receive them through the normal workspace workflow and cannot recover readable content if both are lost.
Shared access and history
The app checks account membership and editing eligibility, records signed-in actor identifiers, and retains assessment snapshots and superseded records. Business responsibility labels identify your internal process. A shared decryption key allows its holder to read and alter a copy outside the app; removing membership cannot revoke copies or keys already retained. The history is not a tamper-proof or independently signed audit log. Use endpoint controls and your organisation's approval procedures.
Saving and restoring
Concurrent folder saves retain separate revisions for review rather than silently merging changes. Validate the selected company and recovery credentials before restoring. Browser clearing, device loss or storage failure can affect browser-held recovery copies, so periodically export backups to a separate approved location and test recovery.
Document processing and exports
PDF reading and English/Arabic OCR run locally with bundled libraries. Extracted information requires human review. Encrypted backup files remain encrypted; evidence-package ZIP exports contain readable reports and original documents and must be stored and shared appropriately.
Application controls
The app uses a Content Security Policy, locally bundled document libraries, verified-email checkout activation, rate-limited password recovery, restricted billing access and database membership checks. These controls do not constitute a security certification or guarantee against compromise. Independent penetration testing, broader device testing and ongoing dependency reviews remain necessary operational work.
Contact
Report a security concern to consult@thevatguide.ae. Never include your workspace password or recovery key.